TL;DR:

  • AI meeting transcription tools (Otter.ai, Fireflies.ai, tl;dv, Copilot for M365) auto-join your video calls and produce searchable transcripts — useful, but they record everything
  • Under UK GDPR, you must inform all participants that a call is being recorded and transcribed, and have a lawful basis for doing so — verbal consent during the call is not sufficient on its own
  • Data stored in the US or other non-EEA countries creates transfer compliance obligations — check your vendor’s data processing agreement and storage location before switching on

You’ve probably been on a video call where a bot with a name like “Fireflies.ai Notetaker” joins the meeting. It silently records everything, produces a transcript, and saves it to a shared workspace that your whole team can search. Very convenient. Also a fairly significant data protection issue if you’re handling client conversations, financial information, or sensitive business discussions.

What These Tools Actually Do

AI meeting transcription tools work as virtual participants that join your Zoom, Teams, or Google Meet calls automatically. They record audio (sometimes video), convert speech to text, identify different speakers, and produce searchable transcripts with action items extracted.

The main tools UK businesses currently use:

  • Otter.ai — US-based, connects to your calendar and auto-joins meetings. Stores recordings and transcripts in the US.
  • Fireflies.ai — US-based, similar auto-join model. Has GDPR compliance documentation but stores data in the US.
  • tl;dv — Berlin-based, marketed as GDPR-compliant with EU data residency options.
  • Microsoft Copilot for M365 — Integrated into Teams, follows Microsoft’s data residency settings (data can be stored in the UK/EU depending on your M365 tenant configuration).
  • Zoom AI Companion — Built into Zoom, data storage region follows your Zoom account configuration.

The distinction matters: where is the transcript and recording stored, and what are the terms under which the vendor can process your data?

The UK GDPR Issues

You must inform participants. Under UK GDPR, recording a conversation involving identifiable individuals is processing personal data. You need a lawful basis (usually legitimate interests or consent), and you must provide a privacy notice to participants before the recording begins.

A bot joining a call and recording without explicit prior notice to all participants is likely unlawful — particularly for external client calls where those clients are not your employees and haven’t agreed to your data processing terms.

“The bot was listed in the participants” is not consent. Some business owners assume that having the AI tool appear in the participant list counts as sufficient notice. It doesn’t. Notice needs to be clear and given in time for participants to make an informed decision about whether to join.

Practical minimum compliance steps:

  • State clearly at the start of every recorded call: “This call is being recorded and transcribed using [tool name]. If you’d prefer we don’t record, please let me know.”
  • Add a note to your meeting invitations for external meetings: “This meeting may be transcribed using AI tools for note-taking purposes.”
  • Have a privacy notice (even a brief one) that covers AI transcription and link to it from your email signature or meeting booking system.

Confidentiality Risks You May Not Have Considered

Think about what happens during client calls:

  • Legal advice discussions
  • Financial planning details
  • Personal information about third parties
  • Commercial negotiation positions
  • Strategies, pricing, and supplier relationships

All of this gets transcribed, stored on a third-party US server, and made searchable by everyone in your company who has access to the tool’s workspace. If your business is subject to confidentiality obligations (solicitors, accountants, healthcare providers), this is a significant professional risk on top of the GDPR obligations.

Check your professional regulatory requirements. Solicitors are subject to SRA obligations around client confidentiality. Accountants under ICAEW/ACCA have similar obligations. Healthcare providers have additional restrictions. If in doubt, consult your professional body guidance before enabling AI transcription for client meetings.

Choosing a More Privacy-Respecting Option

If you want to use AI meeting tools compliantly, prioritise:

EU/UK data residency. Tools like tl;dv offer EU data storage. Microsoft Copilot for M365 follows your tenant’s data residency settings — if you’re on M365 Business with a UK/EU tenant, your data stays in that region.

Data processing agreements (DPAs). Any tool processing personal data on your behalf must sign a DPA with you. Otter.ai and Fireflies both offer DPAs — download and review them before using the tools for external client meetings.

Auto-join controls. Disable automatic bot joining. Instead, manually start transcription only when you’ve confirmed all participants are aware and have consented.

Retention limits. Configure the tool to auto-delete transcripts after 30-90 days. Indefinitely retained recordings of client meetings are a liability in the event of a data breach.

A Simple Policy for UK SMBs

If you want a practical policy without hiring a data protection consultant:

  1. Disable auto-join in your transcription tool settings.
  2. Always announce recording at the start of any transcribed call, and offer participants the option to object.
  3. Don’t transcribe calls involving legal advice, sensitive personal information, or contractual negotiations with external parties unless you’ve obtained explicit consent.
  4. Use Copilot for M365 or tl;dv (EU storage) rather than Otter.ai or Fireflies for any calls involving personal data.
  5. Set auto-deletion for transcripts after 60 days unless there’s a specific reason to retain them.
  6. Tell your staff. If you’re using these tools, your team needs to know the policy — including not to discuss client data on meetings they know are being recorded by a tool with broad team access.

AI meeting tools are genuinely useful for following up on action items and searching past conversations. They’re worth using — with controls. The ICO has signalled increasing scrutiny of AI tools in business contexts, and the risks of non-compliance (particularly reputational damage from a client complaint) outweigh the inconvenience of a brief call announcement.